An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "3.9.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.5"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.6"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.7"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.8"
},
{
"introduced": "0"
},
{
"last_affected": "3.10.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.11.0"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "21"
},
{
"introduced": "0"
},
{
"last_affected": "22"
},
{
"introduced": "0"
},
{
"last_affected": "23"
},
{
"introduced": "0"
},
{
"last_affected": "24"
},
{
"introduced": "0"
},
{
"last_affected": "24.1"
},
{
"introduced": "0"
},
{
"last_affected": "24.2"
},
{
"introduced": "0"
},
{
"last_affected": "24.3"
},
{
"introduced": "0"
},
{
"last_affected": "24.4"
},
{
"introduced": "0"
},
{
"last_affected": "24.5"
},
{
"introduced": "0"
},
{
"last_affected": "24.6"
},
{
"introduced": "0"
},
{
"last_affected": "25"
},
{
"introduced": "0"
},
{
"last_affected": "26"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-4960.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "247.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "248.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "249.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "250.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "251.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "252.0"
}
]
}
]